It`s not a good decision, because in a futere i planning to implement IDS on ASA and "viewing" not real IP adresses - not good

Please, help or give a advice how to implement nat source through 2 ISPs without implementing a nat outside source

Thanks

With best wishes, Vladimir

Xcuse for my English

Vladimir

Absolutely nothing wrong with your English at all

The solution you are using is the way to do it ie. NAT the incoming source addresses.

The only other thing i can think of is to use PBR on your core switch with the recursive next-hop feature (if it is supported). So traffic going from 172.19.1.250 to the internet has it's next-hop set to border1_2821 which would then send it back to the correct router.

Or could you implement PBR on border2_2821 on the inside interface so that any traffic coming in from 172.19.1.250 destined for the internet is sent back out to border1_2821.